PaperCut Software: Unknown PaperCut NG/MF vulnerability is under active attack

PaperCut Software: Unknown PaperCut NG/MF vulnerability is under active attack

Critical PaperCut NG/MF Vulnerability Under Active Exploitation

PaperCut Software has issued an urgent warning about an unpatched vulnerability in its PaperCut NG and PaperCut MF print management solutions, which is being actively exploited in the wild. The company confirmed customer incidents and is prioritizing the investigation, though specific details including indicators of compromise (IoCs) remain undisclosed.

What is PaperCut NG/MF?

  • PaperCut NG is a print management tool for offices, schools, and organizations, monitoring and controlling printing from computers and servers.
  • PaperCut MF is an enhanced version designed for multi-function office copiers (print, scan, fax), integrating directly with devices from major brands via touchscreen interfaces. Both versions rely on a central Application Server, typically one per organization, which acts as the system’s core.

The Vulnerability & Exploitation Risk
The flaw appears to be remotely exploitable, prompting PaperCut to urge immediate action: restrict public internet access to the Application Server, limiting connections to trusted internal IP addresses only. While the vendor has not yet released technical specifics, it advised users to monitor for signs of compromise, including:

  • Security alerts from intrusion detection, endpoint protection, or network monitoring tools particularly suspicious activity linked to pc-app.exe.
  • Missing, truncated, or deleted server.log files.
  • Error logs containing:
    • ERROR No suitable driver found for jdbc:no:x
    • ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST

Even without detected anomalies, organizations should enforce firewall rules or network access controls to block untrusted external access to the server’s web interfaces.

Historical Context & Threat Landscape
This is not the first time PaperCut vulnerabilities have drawn attacker attention. In 2023, Clop and LockBit ransomware affiliates exploited two known flaws CVE-2023-27350 (remote code execution) and CVE-2023-27351 (information disclosure) to breach systems. The current incident underscores the ongoing targeting of print management software, a critical but often overlooked attack surface.

PaperCut has committed to releasing further details as its investigation progresses. Organizations using affected versions are advised to follow the vendor’s mitigation guidance pending a patch.

Source: https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/

PaperCut Software TPRM report: https://www.rankiteo.com/company/papercut-software

"id": "pap1787833729",
"linkid": "papercut-software",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Organizations using PaperCut NG '
                                              'or PaperCut MF',
                        'industry': 'Print Management Software',
                        'name': 'PaperCut Software',
                        'type': 'Vendor'}],
 'attack_vector': 'Remote Exploitation',
 'customer_advisories': 'Organizations using affected versions should follow '
                        'vendor mitigation guidance.',
 'description': 'PaperCut Software has issued an urgent warning about an '
                'unpatched vulnerability in its PaperCut NG and PaperCut MF '
                'print management solutions, which is being actively exploited '
                'in the wild. The company confirmed customer incidents and is '
                'prioritizing the investigation, though specific details '
                'including indicators of compromise (IoCs) remain undisclosed.',
 'impact': {'systems_affected': 'PaperCut NG and PaperCut MF Application '
                                'Servers'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Print management software is a critical but often '
                    'overlooked attack surface. Organizations should enforce '
                    'strict access controls and monitor for suspicious '
                    'activity.',
 'recommendations': 'Restrict public internet access to PaperCut Application '
                    'Servers, monitor for signs of compromise, and follow '
                    'vendor mitigation guidance pending a patch.',
 'references': [{'source': 'PaperCut Software Advisory'}],
 'response': {'communication_strategy': 'Vendor advisory to monitor for signs '
                                        'of compromise and enforce firewall '
                                        'rules',
              'containment_measures': 'Restrict public internet access to the '
                                      'Application Server, limit connections '
                                      'to trusted internal IP addresses only',
              'enhanced_monitoring': 'Monitor for security alerts, '
                                     'missing/deleted log files, and specific '
                                     'error logs'},
 'stakeholder_advisories': 'Vendor advisory to restrict access and monitor for '
                           'anomalies.',
 'title': 'Critical PaperCut NG/MF Vulnerability Under Active Exploitation',
 'type': 'Vulnerability Exploitation'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.